For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 6Question 03
    Easy1 markMultiple Choice
    Domain 1.1: Secure AccessCognitoSecurityAuthentication

    AWS SAA-C03 · Question 03 · Domain 1.1: Secure Access

    A mobile application needs to authenticate users using their social media accounts (Facebook, Google) and then grant them temporary access to upload photos directly to an Amazon S3 bucket.<br/><br/>Which AWS service combination should a solutions architect use?

    Answer options:

    A.

    AWS IAM users and AWS STS

    B.

    Amazon Cognito User Pools and Amazon Cognito Identity Pools

    C.

    AWS IAM Identity Center (AWS SSO) and Amazon S3

    D.

    Amazon API Gateway and AWS Lambda

    How to approach this question

    Differentiate between workforce identity and consumer identity services.

    Full Answer

    B.Amazon Cognito User Pools and Amazon Cognito Identity Pools✓ Correct
    Cognito Identity Pools (Federated Identities) enable you to create unique identities for your users and federate them with identity providers. With an identity pool, you can obtain temporary, limited-privilege AWS credentials to access other AWS services.

    Common mistakes

    Confusing Cognito User Pools (authentication) with Identity Pools (authorization/AWS credentials).
    Question 02All questionsQuestion 04

    Practice the full AWS SAA-C03 Practice Exam 6

    65 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company has multiple AWS accounts in an AWS Organizations organization. The security team wants...MediumQ02A company has two AWS accounts: Account A for development and Account B for production. Developer...MediumQ04A company is running an application on Amazon EC2 instances. The application needs to connect to ...MediumQ05A company has 50 AWS accounts managed by AWS Organizations. The IT team wants to implement a cent...EasyQ06A company wants to restrict access to an Amazon S3 bucket so that only requests originating from ...Medium
    View all 65 questions →